PatchSiren

Bolt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Bolt CVE published 2026-05-29

CVE-2026-39229

CVE-2026-39229 documents a SQL injection vulnerability in Bolt CMS through version 3.7.0, specifically within the 'order' parameter of content listing pages. The vulnerability resides in the OrderDirective component and can be exploited by an authenticated attacker with low-level privileges to extract sensitive information. The CVSS v3.1 score of 6.5 (MEDIUM severity) reflects network attack vector, low a [truncated]